← The Desk 2026-07-17 The Wire
The Perimeter Site

Patch your SharePoint and edge gear first

Gus Tavares
2026-07-17
# Patch your SharePoint and edge gear first If you're running a ten-person shop, you don't have a security operations center. You have a person—maybe you, maybe a contractor—who spends Friday afternoon praying the updates don't break the printer. You cannot patch everything. If you try, you'll spend your entire payroll on administrative overhead and still miss the one hole that actually matters. The goal isn't a perfect audit. The goal is to not be the easiest target on the block. This week, the noise is loud. 23andMe is dominating the cycle with over 110 stories as bankruptcy settlements and data leaks keep the headlines churning. It’s a disaster for them, but it's a distraction for you. You aren't 23andMe. You don't have millions of genetic profiles to lose. You have a few spreadsheets, some client contracts, and a payroll file. Stop looking at the drama and look at the CISA Known Exploited Vulnerabilities (KEV) list. That is the only list that matters for a small budget. It doesn't tell you what *could* happen; it tells you what *is* happening. Right now, Microsoft SharePoint is the primary fire. Two specific holes, CVE-2026-56164 and CVE-2026-58644, are being hit. CVE-2026-56164 alone has triggered 9 separate stories this week. If you host your own SharePoint server and it's pointed at the open web, you are effectively leaving your front door unlocked during a burglary wave. For a global enterprise, patching a fleet of SharePoint servers is a choreographed dance involving staging environments, change management boards, and a team of twenty people. For you, it’s a few clicks and a restart. The cost of failure is the same, but the cost of the fix is vastly lower for the small firm. Do it now. The federal deadline for these is July 19. That's three days away. Next, look at your edge. If you use SonicWall SMA1000 appliances, you've got two new problems: CVE-2026-15409 and CVE-2026-15410. These are code injection and SSRF vulnerabilities. In plain English: someone can trick your gateway into doing things it shouldn't. The second-order effect here is what people miss. If your edge gateway is popped, the attacker isn't just "in the network." They now have a trusted vantage point to sniff every single credential your employees use to log in. They don't need to hack your users; they just need to wait for them to type their passwords. Then there are the Fortinet FortiSandbox holes (CVE-2026-25089 and CVE-2026-39808). If you have this gear, patch it. It’s internet-facing and it’s exploited. Now, let's talk about what can wait. You'll see a lot of talk about the 622 flaws Microsoft patched in their latest cycle. That number is designed to make you panic and buy a managed security service. Ignore the bulk of it. Unless a CVE is on the KEV list or has a public exploit script being shared on GitHub, it's a lower priority than your lunch. The Oracle E-Business Suite vulnerability (CVE-2026-46817) can wait until next week. Unless you're running a massive, legacy ERP system for a mid-sized manufacturing plant, you probably don't even have this installed. The Cisco IOS vulnerability (CVE-2008-4128) is from 2008. Yes, it was added to the KEV recently, but if you're still running 18-year-old Cisco firmware on your primary routers, you have a hardware problem that a patch won't fix. Some will argue that you should patch everything regardless of exploitation status to maintain "hygiene." This is the advice of people who get paid by the hour to maintain the systems. In a ten-person shop, time is your most expensive resource. Spending four hours patching a low-risk internal vulnerability while your SharePoint server is wide open isn't "hygiene"; it's negligence. The most boring controls are still the most effective. If you can't patch immediately, put the service behind a VPN or a strict IP allow-list. It's a free mitigation that shrinks your attack surface from "the whole world" to "just my office." Enterprise firms spend millions on "visibility tools" to see where they are vulnerable. You don't need a dashboard. You need a list of what's facing the internet and a commitment to update those things first. If you're feeling overwhelmed, remember that attackers aren't usually hunting for you specifically. They are casting a wide net. By patching the KEV list, you're simply removing yourself from the easy-catch bucket. Check your SharePoint version and your SonicWall firmware before you leave on Friday.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.